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Qualys API — Tracking API Usage 


Overview 


You can track API usage by a user without the need to provide user credentials such as the username 
and password. 


API usage can be tracked using the X-Powered-By HTTP header which includes a unique ID generated for 
each subscription and a unique ID generated for each user. Once enabled, the X-Powered-By HTTP 
header is returned for each API request made by a user. 


Contact Qualys Support to get the X-Powered-By HTTP header enabled. 


Format 


The information is returned in the following format: 
X-Powered-By: OQuelys:<POD 1D>:<SUB UUITD>:<USER UUID> 


Where, 


- POD IDis the shared POD or a PCP. Shared POD is USPOD1, USPOD2, etc. (See Identify your 
Qualys Platform for a list of platforms). 

- SUB _UUIDis the unique ID generated for the subscription 

- USER _UUID is the unique ID generated for the user 


For example, 
X-Powered-By: Qualys:USPOD1:f£97/72e2cc-69d6-7ebd-80e6- 
769a931475d8:06198167-43£3-7591-802a-1c400a0e81bl 


You can use the USER_UUID to track API usage per user. 


Samples 
Here are sample outputs showing the X-Powered-By HTTP header for VM/PC and Portal apps. 


Sample output 1: VM and PC 


< HTTP/1.1 200 OK 

< Date: Thu, 14 Sep 2017 09:11:21 GMT 

< Server: Qualys 

< X=-XSo=Provection=: 1 

< X-Content-Type-Options: nosniff 

< X-Frame-Options: SAMEORIGIN 

< X-Powered-By: Qualys:USPOD1 :d9a7e94c-0a9d-c745-82e9- 
980877cc5043: £178af1le-4049-7fce-81lca-75584feb8e93 
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X=Ratelimat=Lamit: 300 
X-RateLimit-Window-Sec: 3600 
X-Concurrency-Limit-Limit: 500 
X=COncurrency-Limit-Running: U 
X-RateLimit-ToWait-Sec: 0 
X-RateLimit-Remaining: 298 
xX=Qualys-Application=Versi on: : QWEhB=3.1 1.0. 0=SNAPSHOT= 
0170914072818#4205 

X-Server-Virtual-Host: qualysapi.qualys.com 
X-Server-Http-Host: qualysapi.qualys.com 
Transfer-Encoding: chunked 

Content-Type: text/xml; charset=UTF-8 


IS LS ES PEIN: FEE BS DN PB DS 


Sample output 1: Portal Apps 


22 9HTITP/ daz: 0.0. OK 

X-Powered-By: Qualys:USPOD1:£972e2cc-69d6-7ebd-80e6- 

7b9a931475d8 :06198167-43£3-7591-802a-1c400a0e81b1 

Content-Type: application/xml 

Transfer-Encoding: chunked 

Date: Mon, 04 Dec 2017. 054360729 GMT 

Server: Apache 

LBDEBUG: NS=10.44.1.12, SERVER=10.44.77.81:50205, CSW=cs-qualysapi- 
443, VSERVER=vs-papi-80, ACTIVE-SERVICES=2, HEALTH=100 


The X-Powered-By HTTP header will be returned for both valid and invalid requests. However, it will not 
be returned if an invalid URL is hit or when user authentication fails. 
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